Feature Data Privacy
Washington MHMDA for Fintech: The GLBA Data Exemption and CPA Enforcement
Washington's My Health My Data Act has a data-level GLBA exemption and uses the Consumer Protection Act for public and private enforcement.
Table of Contents
Washington’s My Health My Data Act (MHMDA) protects consumer health data that often falls outside HIPAA. For a fintech, the difficult question is not simply whether the company is a financial institution. It is whether a particular item of personal information is governed by and processed pursuant to a statute listed in the MHMDA’s exemptions.
The second precision point is enforcement. The MHMDA uses Washington’s Consumer Protection Act (CPA); it does not establish automatic damages for every affected record.
August 17, 2026 correction
Two broad statements require correction:
- GLBA: RCW 19.373.100(2) expressly exempts personal information governed by and collected, used, or disclosed pursuant to GLBA and its implementing regulations. This is a data- and processing-level exemption, not a blanket exemption for every activity of a financial institution.
- Private enforcement: RCW 19.373.090 makes a violation an unfair or deceptive act for purposes of the CPA. The Attorney General’s FAQ describes enforcement by the Attorney General and through private action. A private plaintiff proceeds under the CPA and must establish the elements and remedies available there; the statute does not award an automatic fixed amount per consumer.
Why data-level classification matters
A company can hold multiple classes of information under different legal regimes. For example, information collected and used to provide a regulated financial product may be governed by GLBA, while a separate wellness feature, location-derived health inference, or marketing profile may require a different analysis.
Do not label an entire database “GLBA exempt” merely because one product is financial. Instead, record:
- the data field and source;
- the consumer and jurisdiction;
- the processing purpose;
- the law that governs the collection, use, or disclosure;
- whether the information remains within that governed use; and
- any downstream sharing or inference that changes the analysis.
Counsel should confirm close cases. The statutory text places the exemption on qualifying personal information, not on a company name or charter alone.
Use the mixed GLBA and non-GLBA privacy impact assessment to keep that decision attached to the actual field, source, purpose, and recipient. The broader state privacy GLBA exemption guide can help identify the questions, but Washington’s statutory text controls the Washington analysis.
What can be consumer health data
The MHMDA definition is broader than traditional medical records. It can include information linked or reasonably linkable to a consumer that identifies physical or mental health status, including specified categories such as health conditions, treatment, medication, reproductive or sexual health, biometric data, and precise location information that could indicate an attempt to receive health services.
The definition also includes qualifying health information derived or extrapolated from nonhealth information. The Washington Attorney General’s FAQ gives the example of inferences drawn from purchases: an ordinary toiletry purchase is not necessarily health data, but a business’s inference about a person’s health status from purchase data can be.
For fintechs, review features and models that infer or use:
- medical or pharmacy spending patterns;
- pregnancy, fertility, disability, or mental-health status;
- precise location near health-care services;
- health-related eligibility or risk segments; or
- health attributes produced from transaction, browsing, or device data.
The presence of one of these features does not answer every coverage question. It triggers a field-level review of definition, linkage, purpose, consent, and exemption.
Core operational obligations for covered processing
For processing within scope, the Act contains requirements concerning:
- a separate consumer health data privacy policy linked prominently from the homepage;
- consent for collection or sharing outside what is necessary to provide a consumer-requested product or service;
- separate, signed authorization for a sale of consumer health data;
- consumer rights to access, withdraw consent, and delete;
- processor contracts and instructions;
- security measures appropriate to the data; and
- restrictions on geofencing around entities that provide in-person health-care services for specified tracking, collection, or messaging purposes.
The exact rule depends on the actor, data, purpose, and statutory section. Small-business timing differed, but the operative compliance dates for sections 4 through 9 passed in 2024; the geofencing restriction took effect in 2023.
Enforcement through the Washington CPA
RCW 19.373.090 declares that practices covered by the MHMDA are matters vitally affecting the public interest and that a violation is an unfair or deceptive act or practice, and an unfair method of competition, for purposes of the CPA.
That language supports both public and private CPA enforcement, as the Attorney General’s FAQ states. It should not be converted into a claim that the MHMDA created a freestanding cause of action with automatic per-person damages. Private CPA litigation raises additional questions, including injury to business or property, causation, and available remedies under RCW chapter 19.86.
Litigation should be described as allegations
The federal litigation that included Maxwell v. Amazon.com, Inc., No. 2:25-cv-00261-BJR, was consolidated into In re Amazon Ads SDK Litigation, No. 2:25-cv-00252-BJR (W.D. Wash.). Docket allegations and procedural orders are not findings that the defendants violated the MHMDA.
When monitoring cases, distinguish:
- allegations in a complaint;
- a motion-to-dismiss ruling;
- class-certification decisions;
- settlement terms; and
- a merits judgment.
Do not cite an allegation as if a court adjudicated the statutory scope.
A defensible fintech workplan
1. Build a health-data overlay on the existing data map
Tag potentially health-related fields, inferences, precise location data, model outputs, and vendor-derived segments. Include data that originates as ordinary transaction or device information but is transformed into a health inference.
2. Record each exemption at the field and use level
For a claimed GLBA exemption, document why the information is governed by and collected, used, or disclosed pursuant to GLBA. Reassess if the use changes or the information moves into a separate product or marketing workflow.
3. Separate processors, sharing, and sales
Map recipients and contractual roles. Do not assume that every transfer is a sale or that every service provider falls outside the Act’s sharing rules. Preserve the legal basis and operational controls for each transfer.
4. Test deletion and consent workflows
Verify identity, downstream deletion communications, archived-data handling, withdrawal of consent, and retention of a sales authorization where the statute requires it. Test the workflow with the systems that actually hold the data.
5. Review geofencing and SDKs
Inventory location SDKs, advertising integrations, audience tools, and event data around in-person health-care locations. Contract language should match the technical configuration and actual downstream behavior.
Build an Evidence File for Each Coverage Decision
A spreadsheet label such as “health,” “not health,” or “GLBA” is a conclusion, not evidence. For each material data flow, preserve enough information for a reviewer to reconstruct the decision:
| Evidence item | Why it matters |
|---|---|
| field name, sample value, and data dictionary | shows what the element represents rather than relying on a system label |
| collection source and consumer interface | connects the data to the notice, context, and expectation at collection |
| processing purpose and model use | identifies whether ordinary data becomes a health inference |
| governing-law analysis | explains any GLBA or other statutory exclusion at the data-and-use level |
| recipient and contract role | supports the processor, sharing, or sale classification |
| consent or authorization record | proves the scope, action, version, and timing where required |
| retention and deletion path | shows where copies, derived fields, and downstream transfers are handled |
| reviewer and review trigger | makes the decision accountable when the product or use changes |
Do not treat an inference as outside the map because the underlying input looks ordinary. If a transaction, location event, search, or device signal is transformed into a health-related classification, record both the input and the derived output, along with who can use it and for what purpose.
Test Vendors Against the Actual Data Flow
A generic representation that a provider “complies with privacy law” does not establish the firm’s own coverage or consent position. For analytics, advertising, fraud, identity, and location vendors, confirm the fields transmitted, remote configuration, SDK permissions, provider-derived attributes, onward recipients, retention, deletion capability, and use restrictions.
The contract should reflect the role and approved processing. Testing should confirm that production behavior matches the contract. Preserve network or event evidence, configuration exports, deletion-test results, and any discrepancy remediation rather than relying only on a completed questionnaire.
Reassess when a vendor adds a new attribute, inference, audience, integration, or secondary use. A data flow that originally qualified for a GLBA-related purpose may require a new analysis if it moves into an unrelated marketing, wellness, or profiling workflow.
Keep the Consumer Workflow Consistent
Privacy policy, consent, authorization, access, withdrawal, and deletion processes should use the same data inventory and recipient map. If the consumer-facing workflow omits a derived attribute or downstream recipient that appears in the technical map, treat that mismatch as an issue to resolve—not as permission to narrow the map.
Run scenario tests for at least collection, consent withdrawal, deletion, and a vendor termination. Record system results, downstream communications, failed steps, owner, correction date, and retest evidence. These are implementation recommendations; the exact statutory obligation and timing must be mapped to the applicable MHMDA section and the firm’s role.
Bottom line
Washington MHMDA analysis for a fintech is neither “all bank data is exempt” nor “GLBA never matters.” The statute contains an express data-level GLBA exemption, while covered health data outside that exemption may trigger consent, privacy-policy, deletion, contracting, security, and geofencing duties. Enforcement runs through the Washington CPA, with the Attorney General and private plaintiffs using that framework.
Primary and docket sources
- Washington My Health My Data Act, RCW chapter 19.373
- Washington Attorney General: Protecting Washingtonians’ Personal Health Data and Privacy
- Washington CPA private-action provision, RCW 19.86.090
- In re Amazon Ads SDK Litigation docket, No. 2:25-cv-00252-BJR
This article is for general informational purposes and is not legal advice. Coverage and CPA standing are fact-specific; consult Washington counsel.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does Washington's My Health My Data Act exempt financial institutions covered by GLBA?
Does the MHMDA create a standalone private right of action?
What data can count as consumer health data?
What should a fintech do first?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Keep reading
Related posts.
Data Privacy
Global Privacy Control for Financial Services: A State-by-State Scope Test
A practical Global Privacy Control guide for financial services: state scope, GLBA exemptions, signal handling, testing, and evidence.
Aug 17, 2026
Data Privacy
California Just Fined a Data Broker $116K for Making Opt-Out Too Hard. Your Fintech's Data Practices Are Next.
CalPrivacy ordered LocateSmarter to pay $116,490 over registration and opt-out violations, then fined Cybba $52,400 two days later.
Aug 14, 2026
Data Privacy
Location Data Enforcement in 2026: Kochava, GM/OnStar, and Allstate/Arity
Separate the 2026 Kochava and GM orders, California's GM settlement, Texas's Allstate/Arity suit, and private location-data litigation.
Aug 8, 2026